Emergency server help: get in touch

Fix vCenter root password expired and VCSA disk full (/storage/log)

Recover a vCenter Server Appliance whose root password has expired or whose /storage/log or /storage/seat partition has filled, using the console, chage, VAMI, log cleanup and disk expansion on vCenter 8 and 9.

Published Updated 6 min read

Two problems account for a disproportionate share of vCenter outages: the appliance root password quietly expiring after its default 90-day lifetime, and a storage partition (most often /storage/log or /storage/seat) reaching 100%, which causes services to stop or the vSphere Client to log everyone out. They frequently arrive together, because a full log partition stops the password-expiry warning emails from being sent. This guide applies to VCSA 8.0 U3 and vCenter 9.x, which share the same Photon OS layout.

Applies to VCSA 8.0 U3 and vCenter 9.x

Short answer: For an expired root password, open the appliance VM console, press Enter at the login prompt or reach the bash shell through single-user mode if the account is locked, run chage -l root to confirm, set a new password with passwd, and disable or extend the expiry with chage -M -1 root or in VAMI » Administration » Password expiration settings. For a full /storage/log, log in to the shell, find the largest offenders with du -sh /storage/log/vmware/* | sort -h, clear rotated logs and old core dumps, and if the partition is legitimately too small, grow the corresponding VMDK in vCenter and run /usr/lib/applmgmt/support/scripts/autogrow.sh to expand it.

Recover from an expired root password

Symptoms: SSH and VAMI logins fail with “authentication failed” or “password expired”, while the vSphere Client SSO login still works. Log in from the VM console in the vSphere Client or Host Client, because the console allows the password-change prompt that SSH sometimes suppresses:

login: root
Password: <old password>
You are required to change your password immediately

Enter the old password again and a new one. If the console rejects the old password entirely because the account is locked after failed attempts, reboot the appliance, press e at the GRUB menu, append rw init=/bin/bash to the line beginning with linux, boot with F10, then:

mount -o remount,rw /
passwd root
chage -M -1 root
umount /
reboot -f

vCenter 9 requires the GRUB password (set during deployment) to edit the boot line, so keep it in your secret store.

Once back in, set a sensible expiry policy. In VAMI (https://vcenter:5480) » Administration » Password expiration settings, either disable expiry for root or set the number of days and a valid email address for warnings. From the shell:

chage -l root
chage -M 365 -W 14 root

Diagnose a full partition

Log in to the shell (shell from the appliance shell if you land in the restricted one) and check every partition:

df -h
du -sh /storage/log/vmware/* 2>/dev/null | sort -h | tail -20
du -sh /storage/seat/vpostgres 2>/dev/null
du -sh /storage/core/* 2>/dev/null | sort -h

The common offenders in /storage/log/vmware are vpxd, vsphere-ui, eam, analytics and lookupsvc, each accumulating rotated .gz files when logrotate has fallen behind, plus core dumps in /storage/core after a service crash. /storage/seat grows with tasks, events and statistics retention set too high.

Free space safely

Remove rotated logs and old core dumps, but do not delete the live log a service has open:

find /storage/log/vmware -name "*.gz" -mtime +7 -delete
find /storage/log/vmware -name "*.log.[0-9]*" -mtime +7 -delete
rm -f /storage/core/core.*
journalctl --vacuum-time=7d
df -h /storage/log

If a live log file is enormous, truncate it rather than deleting it (: > /storage/log/vmware/vpxd/vpxd-profiler.log), because a deleted-but-open file does not return its space until the service restarts. For /storage/seat, reduce retention in the vSphere Client » vCenter » Configure » Settings » General » Database (task and event retention, statistics levels), then let the nightly cleanup job reclaim space, or run the SEAT cleanup script from /usr/lib/vmware-vpx/vpxd/ documented for your build.

Restart affected services afterwards:

service-control --stop vsphere-ui vpxd
service-control --start vsphere-ui vpxd
service-control --status --all

Grow the partition

When the partition is simply too small for the environment, shut nothing down: in the vSphere Client edit the appliance VM’s settings, identify the disk backing /storage/log (disk 5 on the standard layout; run lsblk in the appliance to map device names to mount points), increase its size, then in the appliance shell run:

/usr/lib/applmgmt/support/scripts/autogrow.sh
df -h /storage/log

The script extends the LVM volume and file system online. Snapshot the VM before resizing, and remove the snapshot afterwards because disks with snapshots cannot be extended.

Verify

df -h should show every partition under 80%, service-control --status --all should list all services running, and the vSphere Client should log in without the “503 Service Unavailable” banner. Confirm root login works over SSH and note the new expiry date from chage -l root. Consider adding the VAMI health API or an SNMP disk check to your monitoring so the partition never reaches 100% again.

Common pitfall

Deleting everything under /storage/log/vmware with a wildcard, including the directories themselves, stops services from starting because they expect their log directories to exist with the right ownership. Delete files, not directories, and if a service will not start afterwards, recreate its directory owned by the correct service user (check a sibling directory with ls -ld).

VCenter root password expired at a glance

Fix vCenter root password expired and VCSA disk full summary card: For an expired root password, open the appliance VM console, press Enter at the login prompt or reach the bash shell…
In short: For an expired root password, open the appliance VM console, press Enter at the login prompt or reach the bash shell through single-user mode if the account is locked, run chage -l root to confirm, set a new password with passwd, and…

Official documentation: Broadcom TechDocs (VMware), Linux man pages.

Related guides: Fix “The redo log of .vmdk is corrupt” on ESXi and Horizon linked clones · DirectAdmin license errors and update failures: da update, IP/hostname mismatches · cPanel 2026 pricing and licensing explained: Solo, Admin, Pro, Premier and WP Squared.

Frequently asked questions

Does the root password expiry also affect the administrator@vsphere.local account?

No. The SSO administrator follows the SSO password policy under Administration » Single Sign On » Configuration » Local Accounts, with its own default of 90 days. An expired SSO password shows as a login failure in the vSphere Client rather than at the appliance shell.

How long does the autogrow script take to extend a partition?

Usually under a minute; the LVM extend and file system resize happen online with no service restart. The disk resize in the vSphere Client is instant, but it is refused if the appliance has a snapshot.

Can I undo a log cleanup or partition expansion?

Deleted rotated logs are gone, though the support bundle history is rarely needed beyond a week. A partition expansion cannot be shrunk again; the only reverse path is restoring the appliance from a file-based backup onto a fresh deployment.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
VCSA 8.0 U3 and vCenter 9.x
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.